What are the responsibilities and job description for the Vulnerability Management Security Analyst position at University of Notre Dame?
For over 180 years, the University of Notre Dame has been a leading American research university, offering a distinct perspective in higher education. This Catholic institution, based in Notre Dame, Indiana, is driven by a powerful blend of faith and intellectual curiosity, consistently pursuing excellence in education, groundbreaking research, and service to society. Notre Dame fosters a welcoming and vibrant campus where students, faculty, and staff are united in their commitment to creating an inclusive community and making a difference in the world. For individuals passionate about innovation, ethical leadership, and leveraging world-class facilities and renowned academic programs, Notre Dame provides a dynamic and impactful career path.
Job Description
At the University of Notre Dame, protecting our digital environment and safeguarding our community's data is vital to ensuring the University remains a force for good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team.
This position plays a key role in helping OIT and campus technology teams identify, understand, prioritize, and remediate vulnerabilities across endpoint, server, network, identity, cloud, SaaS, application, and third-party environments. The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates findings, manages security exceptions, and provides actionable remediation guidance to system owners. In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame’s security capabilities by improving automation, dashboards, metrics, and workflows.
What You'll Do
Minimum Qualifications:
Job Description
At the University of Notre Dame, protecting our digital environment and safeguarding our community's data is vital to ensuring the University remains a force for good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team.
This position plays a key role in helping OIT and campus technology teams identify, understand, prioritize, and remediate vulnerabilities across endpoint, server, network, identity, cloud, SaaS, application, and third-party environments. The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates findings, manages security exceptions, and provides actionable remediation guidance to system owners. In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame’s security capabilities by improving automation, dashboards, metrics, and workflows.
What You'll Do
- Support the vulnerability management lifecycle through routine scanning, analysis, and validation of security findings.
- Prioritize vulnerabilities based on exploitability, exposure, asset criticality, and data sensitivity.
- Partner with system owners and distributed IT units to coordinate and track remediation progress.
- Monitor, triage, and escalate security events across SIEM, EDR, email, and cloud platforms.
- Assist with incident response by gathering evidence, documenting timelines, and recommending containment.
- Maintain and tune security tools, dashboards, and automated ticketing workflows.
- Contribute to broader security initiatives such as cloud security, identity protection, and risk reviews.
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field, OR an equivalent combination of education and professional experience.
- Working knowledge of cybersecurity operations, vulnerability management, incident response, security monitoring, enterprise technology, and IT risk management principles.
- Knowledge of vulnerability management practices, including scanning, validation, risk-based prioritization, remediation tracking, exceptions, compensating controls, and remediation verification.
- Ability to evaluate vulnerability findings, alerts, logs, endpoint telemetry, network activity, cloud events, and authentication patterns to identify risk and recommend action.
- Strong analytical, problem-solving, documentation, communication, security administration, and stakeholder coordination skills.
- Ability to work in the United States, now or in the future, without visa sponsorship.
- Experience in higher education or another complex, decentralized organization.
- Familiarity with cybersecurity frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, EDUCAUSE guidance, or MITRE ATT&CK.
- Experience with security operations, vulnerability management, ticketing, or endpoint platforms such as CrowdStrike, ServiceNow, Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
- Experience supporting vulnerability remediation, phishing investigations, account compromise response, endpoint investigations, cloud security reviews, or security tool administration.
- Experience with scripting, automation, APIs, dashboarding, or data analysis using Python, PowerShell, Bash, SQL, Excel, or similar technologies.
- Relevant certifications such as Security , CySA , GSEC, GCIH, GCIA, GMON, SSCP, CISSP, or similar credentials.
- Please include a cover letter for full consideration of your application.
- Salary: up to 95K, commensurate with experience
- Deadline to apply (subject to change): Thursday, August 6th, 2026
- This position maintains a Hybrid work arrangement (1-2 days remote based on operational needs and team expectations.)